GSEC Cryptography Application Practice Question
A security administrator is configuring a VPN concentrator to protect data in transit. The requirement is that each VPN session use a unique symmetric key, and that compromise of one session key never reveal another session's key or the long-term authentication secret. Which property must the key exchange provide?
⚠ Common exam trap
Many exam-takers confuse confidentiality of the handshake with forward secrecy, assuming any encrypted key exchange prevents one compromised session key from affecting others when only ephemeral, discarded secrets do.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perfect forward secrecy, so that each session key is derived independently and compromise of one does not expose others or the long-term secret.
Perfect forward secrecy uses ephemeral key agreement such as Diffie-Hellman with per-session values, so the long-term authentication secret never encrypts session keys directly. Even if one session key is later compromised, the ephemeral secrets needed to derive other sessions have been erased, and the long-term secret remains protected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Key encapsulation, so that the long-term secret directly encrypts each session key and guarantees confidentiality of the exchange.
Why it's wrong here
Key encapsulation typically wraps a session key with a long-term public key; if the corresponding long-term private key is later compromised, every wrapped session key can be recovered. That directly violates the requirement that compromise of one session key never reveal another session's key or the long-term secret.
- ✗
Collision resistance, so that two different sessions cannot produce the same derived key material during the handshake.
Why it's wrong here
Collision resistance is a hash function property that prevents two distinct inputs producing the same digest; it does not prevent a compromised long-term secret from unwrapping stored session keys. It is unrelated to isolating session keys from each other or protecting the long-term authentication secret.
- ✓
Perfect forward secrecy, so that each session key is derived independently and compromise of one does not expose others or the long-term secret.
Why this is correct
Perfect forward secrecy derives each session key from ephemeral values that are discarded after the exchange, so a later compromise of a session key or long-term secret cannot reconstruct other sessions' keys. This directly satisfies the requirement that no session key reveal another or the long-term authentication secret.
- ✗
Non-repudiation, so that each VPN endpoint can prove it participated in the session and cannot deny sending traffic.
Why it's wrong here
Non-repudiation is a property of digital signatures that binds a party to a message; it does not isolate session keys from one another. It addresses accountability rather than the confidentiality requirement that one session key compromise cannot expose other keys or the long-term authentication secret.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
About these practice questions
This GSEC question is part of Courseiva's 351-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.